SQL Injection Vulnerabilities in Mantis from MantisBT
CVE-2005-4519
Currently unrated
What is CVE-2005-4519?
The Mantis Bug Tracker versions prior to 1.0.0rc4 are susceptible to multiple SQL injection vulnerabilities. Attackers can exploit these flaws through the manage user page (manage_user_page.php) by manipulating the 'prefix' and 'sort' parameters. Additionally, vulnerabilities are present in the 'sort' parameter in the view_all_set.php file, enabling remote attackers to execute arbitrary SQL commands, which can lead to unauthorized data access or manipulation.
